On October 21, 2024, the U.S. Federal Trade Commission's Trade Regulation Rule on the Use of Consumer Reviews and Testimonials (16 CFR Part 465) took effect. It's the most significant U.S. regulation of online reviews ever enacted — and it changes the compliance landscape for every business that collects, displays, or purchases reviews. Here's what the rule covers, what it bans, who's exposed, and how to be structurally compliant rather than policy-compliant.
How we got here
FTC proposes the rule
The FTC issues a Notice of Proposed Rulemaking, citing overwhelming evidence that fake reviews harm consumers and honest businesses. Public comment period opens.
Final rule announced
The FTC votes unanimously (5–0) to issue the final rule. Commissioner statements emphasize that the rule targets deceptive practices, not honest review collection.
Rule takes effect
16 CFR Part 465 becomes enforceable. The FTC can seek civil penalties of up to $51,744 per violation.
First enforcement: SiteJabber
The FTC issues a formal order against SiteJabber for publishing reviews from consumers who had never received the products they reviewed — collected at point of sale, before product receipt.
What the rule bans
1. Fake or false reviews Banned
Reviews that misrepresent that the reviewer had genuine experience with a product, service, or business. This covers reviews by people who never used the product, reviews the business wrote about itself, and reviews the business paid someone to write without disclosure.
2. Buying or selling reviews Banned
Purchasing or selling reviews — including reviews that express a particular sentiment (positive or negative). This closes the loophole where businesses claimed they were paying for "honest" reviews, not positive ones.
3. Insider reviews without disclosure Banned
Reviews written by company insiders — officers, managers, employees, or their relatives — that don't clearly disclose the reviewer's connection to the business. An employee CAN review their employer's product if they disclose the relationship. They can't pretend to be an unconnected customer.
4. Review suppression Banned
Using threats, intimidation, or false accusations to prevent or remove negative reviews. This includes legal threats against reviewers (a common tactic) and terms of service that attempt to prohibit negative reviews. The Consumer Review Fairness Act (2016) already addressed this; the FTC rule strengthens it.
5. Fake indicators of social media influence Banned
Buying or selling fake followers, views, likes, or other social media influence indicators generated by bots or hijacked accounts — when used for commercial purposes.
Who it applies to
The rule applies to businesses, review platforms, and intermediaries involved in collecting, moderating, displaying, or purchasing reviews. This includes:
- Businesses that collect and display reviews on their own websites
- Review platforms (Trustpilot, Yotpo, Judge.me, Signed Reviews, etc.)
- Marketing agencies that manage review collection for clients
- E-commerce platforms that host reviews (Amazon, Shopify, etc.)
- Anyone who buys, sells, or facilitates fake reviews
Penalties
The FTC can seek civil penalties of up to $51,744 per violation under the FTC Act. A business that manufactured 50 fake reviews could theoretically face penalties exceeding $2.5 million. In practice, the FTC has indicated it will prioritize cases involving systematic deception, large-scale operations, and knowing violations — but the per-violation structure means the exposure is real for businesses of any size.
How to be compliant (structurally, not just by policy)
Most businesses approach FTC compliance as a policy question: "What do our terms of service say? What's our moderation process?" This is necessary but insufficient. A policy is a promise; a structural guarantee is a property of the system.
The compliance spectrum
Policy compliance (weak): "We have a policy against fake reviews. We moderate reviews before publishing. We require reviewers to confirm they purchased." This is what gets businesses in trouble — policies are only as good as their enforcement, and enforcement is expensive, inconsistent, and reactive.
Structural compliance (strong): "Our review system physically cannot accept a review without an independently verified payment. A neutral third party — the payment processor — confirms the charge. If the charge is refunded, the review is hidden automatically. No human moderation required to enforce this — it's built into the code." This is compliance by construction: the system makes violations impossible, not just prohibited.
What this means for your review strategy
The FTC rule changes the risk calculus for review collection:
- Open platforms (Level 0–1) — highest risk. Anyone can post; verification is minimal. Your business could be penalized for fake reviews on your profile, even if you didn't create them. The FTC's theory: by choosing an unverified platform, you assumed the risk of fake reviews appearing on your profile.
- Merchant-supplied platforms (Level 3) — medium risk. Verification is stronger, but you control the verification data. If a fake review appears, you're the most likely source — whether intentional or not. The FTC's SiteJabber action shows they will hold platforms and businesses accountable for systematic verification failures.
- Processor-attested platforms (Level 4) — lowest risk. Verification is independent. You cannot fake a review without committing payment fraud against Stripe, which carries its own severe penalties. The system is structurally compliant; you don't need to trust your policies because the code enforces the compliance.
Collect structurally compliant reviews →
Related: What "Verified Buyer" Actually Means · How Fake Reviews Work · FTC Fake Review Laws